An ISO 27001 asset-based risk assessment starts from the things your organization needs to protect, such as systems, data sets, people and facilities, and works out what could go wrong with each one. It is the approach most teams picture when they hear the words information security risk assessment, and it remains popular because it is easy to explain and easy for auditors to follow.
This guide explains how the asset-based method works, what ISO/IEC 27001:2022 actually requires, how to keep the asset list manageable and where the approach tends to go wrong. It also shows how it compares with scenario-based methods.
Free gap assessment
Where do you actually stand against ISO 27001?
Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.
Run the free ISO 27001 gap assessment → or View premium report sample
What ISO 27001 requires of the risk assessment
Clause 6.1.2 of ISO/IEC 27001:2022 requires you to define and apply an information security risk assessment process. The process must set risk acceptance criteria and criteria for performing assessments, produce consistent, valid and comparable results, identify risks to the confidentiality, integrity and availability of information within the scope of the management system, identify risk owners, analyze the likelihood and consequences, and evaluate the risks against your criteria. You must keep documented information about the process and its results.
Free ISO 27001 risk assessment
Which of your risks sit above your appetite line?
Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free risk assessment → or View premium report sample
The standard does not say that you must work from assets. The 2013 edition tied the process to assets, threats and vulnerabilities in its guidance, while the 2022 edition leaves the method open. That means an ISO 27001 asset-based risk assessment is a choice, not a requirement, and you should be able to explain why you chose it. Our overview of the ISO 27001 risk assessment covers the full clause and the alternatives.
How an ISO 27001 asset-based risk assessment works
The method follows a chain: asset, threat, vulnerability, risk. You list the assets, decide which are valuable enough to assess, identify what threatens each one, identify the weaknesses that let those threats succeed, and then rate the resulting risk. The steps below describe a practical sequence.
- Build the asset inventory. Include information, applications, infrastructure, suppliers, people with unique knowledge and physical locations that fall within scope.
- Assign an owner to every asset. The owner is the person accountable for the asset, who can accept risk and fund treatment.
- Value the assets. Rate the effect on confidentiality, integrity and availability if the asset were compromised.
- Identify threats and vulnerabilities. Use a maintained threat list and the results of scans, audits and incidents.
- Rate likelihood and consequence. Use the written scales from your methodology.
- Decide treatment and record it. Link each treated risk to the controls in your Statement of Applicability.
Building the asset inventory for an asset-based risk assessment
The asset inventory is where most of the effort goes, and where the method is most likely to become unmanageable. A company with thousands of endpoints and hundreds of applications cannot rate every item separately. Group similar assets and rate the group. All standard laptops with the same build and controls can form one asset class, and all customer-facing web applications hosted on the same platform can form another.
| Asset type | Examples | Useful grouping |
|---|---|---|
| Information | Customer records, source code, contracts | By data classification |
| Applications | ERP, CRM, HR system | By business process supported |
| Infrastructure | Servers, networks, cloud tenancies | By platform and environment |
| People | Administrators, key engineers | By role |
| Suppliers | Cloud provider, payroll bureau | By criticality |
| Facilities | Offices, data rooms | By site |
Start with the information and the business processes that depend on it, then work outward to the systems and suppliers that hold or process that information. This keeps the inventory tied to business value rather than to a purchasing list.
Identifying threats and vulnerabilities in the assessment
Before you begin, decide how detailed the ISO 27001 asset-based risk assessment needs to be for your size and sector, and write that decision into the methodology so auditors can see it was deliberate.
A threat is something that could cause harm, such as ransomware, insider misuse, hardware failure, supplier outage or accidental deletion. A vulnerability is a weakness that lets the threat succeed, such as missing patches, weak access reviews, unencrypted backups or untrained staff. Risk exists only where both are present for a given asset.
Use several sources: threat catalogues, incident history, penetration test and vulnerability scan results, audit findings, supplier reports and reports from your own staff. Avoid copying a very long generic list into your register. Choose the threats that are realistic for each asset class and record why the others were excluded.
Rating likelihood and consequence
Use scales that are written down, with each level defined. A four or five level scale is common. Anchor likelihood to observable facts, such as how often the event has occurred here or elsewhere and how strong the controls are. Anchor consequence to effects on operations, customers, legal obligations and finances. Confirm that the same scales are used across the whole assessment, because auditors will look for consistency. The ISO 27001 risk assessment methodology guide shows how to write and test those scales.
Risk owners, treatment and the Statement of Applicability
Every rated risk needs an owner. Clause 6.1.2 asks you to identify risk owners, and it is a distinct role from the asset owner, although in practice the same person often holds both. Owners approve the treatment and accept residual risk. See our guide to the ISO 27001 risk owner for how to assign and document that accountability.
Clause 6.1.3 then requires a risk treatment process: choose treatment options, determine the controls needed, compare them with Annex A to check that nothing necessary has been omitted, and produce a Statement of Applicability. ISO/IEC 27001:2022 Annex A contains 93 controls in four themes: organizational, people, physical and technological. Each risk you treat should trace to at least one control, and each control in your Statement of Applicability should have a reason. The ISO 27001 risk treatment plan article explains how to link the two records.
Strengths and weaknesses of an ISO 27001 asset-based risk assessment
The strengths are clarity and audit familiarity. Everyone understands that a server has a value and can be attacked, and an asset register is useful for other purposes such as change management and disposal. The weaknesses are volume and rigidity. It is easy to produce thousands of rows that nobody reads, and the method can miss risks that do not attach neatly to one asset, such as a bad decision, a poorly understood dependency or a shared process failure.
ISO/IEC 27005:2022, the guidance standard on information security risk management, describes both an asset-based approach and an event-based, or scenario, approach and allows you to use either or combine them. Many organizations use assets for infrastructure and scenarios for strategic threats. Our comparison of ISO 31000 and ISO 27005 explains where each standard fits.
Common audit findings
Auditors regularly find asset lists with no owners, assets valued without reference to the scale, threats copied from a template with no link to the organization, risks with no treatment or approval, and a register last updated at certification. Another frequent finding is a Statement of Applicability that cannot be traced to the risk assessment. Review your records for these before the certification body does.
Keeping the ISO 27001 asset-based risk assessment current
For the ISO 27001 asset-based risk assessment to stay useful, set review triggers: new systems, major changes, incidents, supplier changes, new threats and each management review. Assign a named person to keep the inventory current, and compare it with real sources such as the configuration database, cloud accounts and purchasing records. An inventory that matches reality is far more valuable than a beautifully formatted one that does not.
Working from a finished structure
If you want to avoid building the register from nothing, the ISO 27001 Risk Assessment Report and Workbook provides a structured report and working register aligned to clause 6.1.2. You can also compare where your controls stand with an ISO 27001 gap assessment before you start. Either way, check the result against your own scope and your licensed copy of the standard, and you can read the official summary of the standard at ISO/IEC 27001 on iso.org.
ISO 27001 asset-based risk assessment FAQ
Does ISO 27001 require an asset-based approach?
No. Clause 6.1.2 of the 2022 edition requires a defined risk assessment process but does not prescribe assets, threats and vulnerabilities. You can use an asset-based, scenario-based or combined approach if it produces consistent and comparable results.
Do I have to assess every asset individually?
No. Group similar assets into classes and rate the class, provided the controls and exposure are genuinely alike. Assess individually only where an asset is unique or critical.
What is the difference between an asset owner and a risk owner?
An asset owner is accountable for the asset, while a risk owner is accountable for a specific risk and has authority to approve its treatment. They are often the same person, but the roles are separate and should both be documented.
How often should the assessment be repeated?
Review it at planned intervals, commonly at least annually, and whenever significant changes or incidents occur. The standard expects the assessment to be repeated at planned intervals or when significant changes are proposed.
What should the risk assessment produce for an auditor?
Auditors expect the documented process, risk acceptance criteria, the asset inventory with owners, the risk register with scores and treatment decisions, the treatment plan and the Statement of Applicability, all consistent with one another.